Lead AI Security Engineer
Lead AI Security Engineer (Agentic SOC)
Location: McLean/Tysons, VA | On-site (5 days/week)
We are pioneering the next generation of cyber defense by building an Agentic Security Operations Center (SOC). Are you ready to build the future of autonomous, agentic defense? It is time to move beyond reactive alerting. If you are passionate about creating self-orchestrating, context-aware AI systems capable of autonomous triage and proactive threat mitigation, we want you on our team.
ABOUT THE TEAM
We are pioneering the next generation of cyber defense by building an Agentic Security Operations Center (SOC). Our mission is to move beyond reactive alerting by creating self-orchestrating, context-aware AI systems capable of autonomous triage, semantic correlation, and proactive threat mitigation. In this role, you will leverage emerging AI capabilities to reimagine how we defend our organization.
THE OPPORTUNITY
The AI SOC Engineering team is at the center of bringing our vision for AI-driven security to This is a squad of builders operating at the intersection of Generative AI, software engineering, and offensive/defensive security. We don't just write scripts; we architect the intelligent fabric of our defensive posture. We build and deploy production-grade, proprietary multi-agent systems that empower our human analysts to handle complex incident response with autonomous agents AI in responsible and scalable ways.
WHAT YOU'LL DO
Build & Deploy Agents: Design, test, and deploy autonomous and semi-autonomous AI agents that integrate natively with our enterprise security stack (SIEM, EDR, XDR, and Threat Intel feeds).
Code the Playbooks: Translate traditional, human-centric SOC playbooks and analyst workflows into deterministic and heuristic agentic pipelines (using DAGs and multi-agent routing).
Optimize RAG Pipelines: Design, optimize, and maintain production-grade Retrieval-Augmented Generation (RAG) workflows to inject real-time security context, network topology, and historical incident logs into agent prompts.
LLM Performance Engineering: Continuously evaluate, benchmark, and optimize LLM performance, context window utilization, latency, and cost-efficiency across various models (OSS and commercial).
Design Human-in-the-Loop (HITL): Collaborate deeply with Tier 3 Analysts and Threat Hunters to engineer seamless HITL handoff mechanisms, ensuring agents safely escalate complex anomalies to humans.
Secure the AI: Implement robust security boundaries around our LLM architecture, mitigating risks like prompt injection, data poisoning, model tool-abuse, and addressing the OWASP Top 10 for LLMs .
REQUIRED QUALIFICATIONS
4+ years of professional software engineering experience, with at least 1.5+ years explicitly dedicated to building applications powered by Large Language Models (LLMs)
5+ years of experience programming with Python
2+ years of experience deploying scalable and responsible AI solutions on cloud platforms (e.g., AWS, Google Cloud, Azure)
You love to build systems: You take pride in the quality of your code and possess a deep passion for applying AI to solve complex security challenges.
Security-First Mindset: You blend foundational software engineering with practical security domain knowledge. You understand that the best defenses are built on a bedrock of clean, reliable, and scalable engineering.
Adaptability: You thrive on bringing clarity to big, undefined problems in the security space. You love asking questions, digging deep to uncover the root of threats, and articulating your findings concisely.
Deeply Technical: You possess a strong foundation in engineering and mathematics. Your expertise in software and AI enables you to design intelligent systems that can perform autonomous triage and semantic correlation.
Resilient: You are a trailblazer who can forge new paths to achieve security goals in an evolving threat landscape.
PREFERRED QUALIFICATIONS
Hands-on experience building multi-agent or complex orchestration systems using tools such as LangChain, LlamaIndex, AutoGen, CrewAI, or Semantic Kernel
Proven experience working with production Vector Databases (e.g., Pinecone, Qdrant, Milvus, or Weaviate ) for semantic chunking, embedding generation, and metadata filtering.
Experience interfacing with cybersecurity platforms via REST APIs/Webhooks (e.g., Splunk, CrowdStrike, Microsoft Sentinel, Palo Alto XSOAR).
Experience deploying and scaling AI workloads in containerized cloud environments (AWS, Azure, or GCP using Kubernetes/EKS/AKS)
Understanding of fine-tuning methodologies (LoRA, QLoRA) for smaller, domain-specific open-source models (e.g., Llama 3, Mistral) tailored for security log analysis
Passion for staying abreast of the latest AI research and security systems, and an ability to judiciously apply novel techniques in production.
The base salary range represents a good faith and reasonable estimate of the range at the time of posting. Actual compensation will be dependent on a number of factors including, but not limited to, the candidate’s relevant work experience, qualifications, internal peer equity, and market and business conditions that exist when extending an offer. A discretionary bonus may be awarded in recognition of individual and company performance.
In addition, Appian provides generous benefits offerings that include a 401(k) plan with company match, flexible time off, paid parental leave, medical, dental, and vision plans, life insurance, disability insurance, wellness programs, flexible spending accounts, health savings account contributions, an employee referral bonus program, and learning and development resources. Certain positions may be eligible for equity awards.
Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation, commission, bonus, or benefit plans.
Base Salary Range
$150,000—$275,000 USD